A Large-Scale Empirical Study of Security Patches
Frank Li, Vern Paxson
摘要
Given how the "patching treadmill" plays a central role for enabling sites to counter emergent security concerns, it behooves the security community to understand the patch development process and characteristics of the resulting fixes. Illumination of the nature of security patch development can inform us of shortcomings in existing remediation processes and provide insights for improving current practices. In this work we conduct a large-scale empirical study of security patches, investigating more than 4,000 bug fixes for over 3,000 vulnerabilities that affected a diverse set of 682 open-source software projects. For our analysis we draw upon the National Vulnerability Database, information scraped from relevant external references, affected software repositories, and their associated security fixes. Leveraging this diverse set of information, we conduct an analysis of various aspects of the patch development life cycle, including investigation into the duration of impact a vulnerability has on a code base, the timeliness of patch development, and the degree to which developers produce safe and reliable fixes. We then characterize the nature of security fixes in comparison to other non-security bug fixes, exploring the complexity of different types of patches and their impact on code bases. Among our findings we identify that: security patches have a lower footprint in code bases than non-security bug patches; a third of all security issues were introduced more than 3 years prior to remediation; attackers who monitor open-source repositories can often get a jump of weeks to months on targeting not-yet-patched systems prior to any public disclosure and patch distribution; nearly 5% of security fixes negatively impacted the associated software; and 7% failed to completely remedy the security hole they targeted.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper74
- Understanding the Reproducibility of Crowd-reported Security VulnerabilitiesDongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu 等USENIX Security 2018 · 被引用 138 次
- SEC-bench: Automated Benchmarking of LLM Agents on Real-World Software Security TasksHwiwon Lee, Ziqi Zhang, Hanxiao Lu, Lingming ZhangNeurIPS 2025 · 被引用 86 次
- Finding A Needle in a Haystack: Automated Mining of Silent Vulnerability FixesJiayuan Zhou, Michael Pacheco, Zhiyuan Wan, Xin Xia 等ASE 2021 · 被引用 84 次
- ATTACK2VEC: Leveraging Temporal Word Embeddings to Understand the Evolution of CyberattacksYun Shen, Gianluca StringhiniUSENIX Security 2019 · 被引用 77 次
- Patch based vulnerability matching for binary programsYifei Xu, Zhengzi Xu, Bihuan Chen, Fu Song 等ISSTA 2020 · 被引用 74 次
它引用的顶会 Paper2
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami 等USENIX Security 2016 · 被引用 149 次
- Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid ResponseZhen Huang, Mariana D'Angelo, Dhaval Miyani, David LieS&P 2016 · 被引用 59 次
相关 Paper
- SPIDER: Enabling Fast Patch Propagation In Related Software RepositoriesAravind Machiry, Nilo Redini, Eric Camellini, Christopher Kruegel 等S&P 2020 · 被引用 39 次
- Unveiling the Characteristics and Impact of Security Patch EvolutionZifan Xie, Ming Wen, Zichao Wei, Hai JinASE 2024 · 被引用 2 次
- Vision: Identifying Affected Library Versions for Open Source Software VulnerabilitiesSusheng Wu, Ruisi Wang, Kaifeng Huang, Yiheng Cao 等ASE 2024 · 被引用 1 次
- Tracking patches for open source software vulnerabilitiesCongying Xu, Bihuan Chen, Chenhao Lu, Kaifeng Huang 等FSE 2022 · 被引用 34 次
- Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue ManagementLyuye Zhang, Jiahui Wu, Chengwei Liu, Kaixuan Li 等ISSTA 2025 · 被引用 3 次
